2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3957 | HIGH | 7.4 | 25.6% | Jun 7, 2019 | Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the ... |
| CVE-2019-3956 | — | — | 1.6% | Jun 7, 2019 | Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the ... |
| CVE-2019-12506 | — | — | 1.3% | Jun 7, 2019 | Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remot... |
| CVE-2019-12505 | — | — | 1.3% | Jun 7, 2019 | Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP1001 v1.3C is prone to keyst... |
| CVE-2019-12504 | — | — | 1.9% | Jun 7, 2019 | Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP2002 is prone to keystroke i... |
| CVE-2019-5441 | — | — | — | Jun 7, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12739. Reason: This candidate is a reservation d... |
| CVE-2019-3955 | — | — | 19.1% | Jun 7, 2019 | Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the serv... |
| CVE-2019-2102 | — | — | 0.3% | Jun 7, 2019 | In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were t... |
| CVE-2019-2101 | MEDIUM | 5.5 | 0.4% | Jun 7, 2019 | In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. T... |
| CVE-2019-2099 | — | — | 0.6% | Jun 7, 2019 | In nfa_rw_store_ndef_rx_buf of nfa_rw_act.cc, there is a possible out-of-bound write due to a missing bounds check. This... |
| CVE-2019-2098 | — | — | 0.2% | Jun 7, 2019 | In areNotificationsEnabledForPackage of NotificationManagerService.java, there is a possible permissions bypass due to a... |
| CVE-2019-2097 | — | — | 1.3% | Jun 7, 2019 | In HAliasAnalyzer.Query of hydrogen-alias-analysis.h, there is possible memory corruption due to type confusion. This co... |
| CVE-2019-2096 | — | — | 0.2% | Jun 7, 2019 | In EffectRelease of EffectBundle.cpp, there is a possible memory corruption due to a double free. This could lead to loc... |
| CVE-2019-2095 | — | — | 0.7% | Jun 7, 2019 | In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after free due to a race co... |
| CVE-2019-2094 | — | — | 1.1% | Jun 7, 2019 | In parseMPEGCCData of NuPlayerCCDecoder.cpp, there is a possible out of bounds write due to missing bounds checks. This ... |
| CVE-2019-2093 | — | — | 1.2% | Jun 7, 2019 | In huff_dec_1D of nlc_dec.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to... |
| CVE-2019-2092 | — | — | 0.2% | Jun 7, 2019 | In isSeparateProfileChallengeAllowed of DevicePolicyManagerService.java, there is a possible permissions bypass due to a... |
| CVE-2019-2091 | — | — | 0.2% | Jun 7, 2019 | In GetPermittedAccessibilityServicesForUser of DevicePolicyManagerService.java, there is a possible permissions bypass d... |
| CVE-2019-2090 | — | — | 0.1% | Jun 7, 2019 | In isPackageDeviceAdminOnAnyUser of PackageManagerService.java, there is a possible permissions bypass due to a missing ... |
| CVE-2019-12779 | — | — | 0.7% | Jun 7, 2019 | libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable fil... |
| CVE-2019-12601 | — | — | 1.1% | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3). |
| CVE-2019-12600 | — | — | 1.1% | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3). |
| CVE-2019-12599 | — | — | 1.1% | Jun 7, 2019 | SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection. |
| CVE-2019-12598 | — | — | 1.1% | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3). |
| CVE-2019-10160 | CRITICAL | 9.8 | 5.2% | Jun 7, 2019 | A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 af... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now